Iranian company dealing only with Iranian entities
1395
Privately held
Company score
4.1
insurance
Aَzki is a website for comparing, buying and managing insurance online. With the help of Azki, you can compare and consciously buy all the information you need, including price, insurance coverage and quality of services of different insurance companies.
We are looking for a Senior Cyber Defense Engineer / Blue Team Security Engineer to design, build, and operate our security monitoring and detection capability. The core of this role is detection engineering: building real detections from raw telemetry, not administering an existing SIEM.
Key Responsibilities:
Manage, maintain, and optimize the Splunk SIEM environment.
Onboard and integrate security logs from servers, endpoints, network devices, private cloud platforms, and security tools.
Create and maintain Splunk dashboards, reports, alerts, and searches.
Monitor Splunk performance, data ingestion, indexing, and system health.
Develop new security detection rules and use cases.
Review and tune WAF rules to reduce false positives and improve coverage of web attacks.
Analyze security events and identify suspicious or malicious activity.
Support automation and integration between Splunk and other security tools.
Knowledge of Kubernetes security.
Requirements:
Hands-on experience with Splunk Enterprise and/or Splunk Enterprise Security (ES).
Strong knowledge of Splunk SPL.
Hands-on experience with WAF technologies, including log analysis, custom rule writing, and tuning.
Familiarity with web attacks and the OWASP Top 10, and how to detect them in WAF and web server logs.
Knowledge of MITRE ATT&CK.
Understanding of Windows, Linux, network, endpoint, and Kubernetes logs.
Job Requirements
Gender
Men / Women
ثبت مشکل و تخلف آگهی
ارسال رزومه برای ازکی
برای دیدن سوابق ارسال رزومه، لطفا وارد حساب کاربری خود شوید.